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Abstract 

We introduce a new quantum key distribution protocol that uses d-level quantum 
systems to encode an alphabet with c letters. It has the property that the error rate 
introduced by an intcrcept-and-resend attack tends to one as the numbers c and d 
increase. In dimension d — 2, when the legitimate parties use a complete set of three 
mutually unbiased bases, the protocol achieves a quantum bit error rate of 57.1%. This 
represents a significant improvement over the 25% quantum bit error rate achieved in 
the BB84 protocol or 33% in the six-state protocol. 

1 Introduction 

By sharing a random string of numbers, two parties can encrypt a message in such a 
way that it appears completely random to an eavesdropper. The "one-time pad" is an 
unbreakable method of encryption provided the string is truly random and only used once. 
The problem comes in having sufficiently many strings, called keys, with which to encrypt 
all messages you wish to send. This is called the key distribution problem. 

By allowing the security of the key distribution protocol to be computationally impos- 
sible rather than unconditional, several ingenious methods to distribute keys have been 
developed. Assuming that an eavesdropper does not posses an infinitely large computer, 
cryptographic systems can make use of mathematical problems that are very hard to solve. 
For example, there is no known efficient algorithm to factorize large integers into a product 
of primes (used in the Rivest-Shamir-Adleman algorithm [lj) or to compute the discrete 
logarithm (used in the Diffe-Hellman-Merkle key exchange [2j [3] ) . However, solving these 
mathematical problems is only difficult, not impossible, so that the security of such public 
key protocols relies on the lack of future developments in mathematics and technology 

In 1970, Wiesner proposed a totally new approach to cryptography [4] that was then 
developed by Bennett and Brassard: they presented a key distribution protocol [5], now 
known as BB84, that uses properties of quantum systems to ensure its security. This 
protocol allows two parties, Alice and Bob, to distribute a key such that anyone who 
attempts to listen in on the quantum signals can, in theory, be detected. The eavesdropper, 
Eve, is constrained by the physical laws of quantum mechanics. She cannot perform a 
measurement without introducing a disturbance (Heisenberg's uncertainty principle), copy 



states (no cloning) or split the signal, since it consists of single photons or particles. Other 
protocols such as Ekert's [6] use entangled particles in such a way that Eve essentially 
introduces hidden variables destroying the quantum correlations. It is possible to prove that 
these quantum key distribution (QKD) protocols are secure against all future technological 
and mathematical advanced [H [9] . 

When attempting to implement a QKD protocol a key factor in determining its practical 
success is the error rate introduced by Eve: if it is small, her presence may be masked by the 
system noise. This error rate thus determines the level of technology required to implement 
the protocol and the distance over which Alice and Bob can establish a secure key. We will 
present a protocol that extends the one proposed by Khan et al. [10]. The new approach 
ensures that eavesdropping causes a large error rate and therefore, from an experimental 
point of view, offers a modification that could improve the implementation of existing QKD 
technology. 

The new protocol allows Alice and Bob a great deal of freedom: the elements of the 
key that they form can be taken from an alphabet of arbitrary size, and encoded using any 
bases of C d . It is equivalent to the protocol presented in [10] when Alice and Bob use a 
two-letter alphabet and corresponds to the SARG protocol [TT] when in addition, they use 
two-dimensional quantum systems. 

In order to better understand the freedom in the choice of bases used by all three parties, 
Alice, Bob and Eve, we will introduce a measure of distance between two bases and show 
how this relates to the error rate. It gives a simple interpretation of the optimal setup for all 
parties: Alice and Bob should use a set of c bases, S, that are as far apart as possible; whilst 
Eve should choose her basis, £, so it minimises the average distance between £ and the 
elements of S. The conclusion then is that for the legitimate parties, the optimal settings 
correspond to so called mutually unbiased (MU) bases or complementary observables. MU 
bases have the property that a measurement in any one of the bases reveals no information 
about the state in all of the other bases; and have been used before in other QKD protocols 

[SUSIE]. 

The paper is organised as follows. In Sec. [2j we will introduce a key distribution 
protocol that encodes a c-letter alphabet using quantum systems of dimension d. In Sec 
[3l we will examine the effect of an eavesdropper by calculating two error rates that allow 
the legitimate parties to detect Eve's intercept-and-resend attack. Sec. 2] will show how 
one of these error rates can be understood as a measure of the distance between the bases 
used by all three parties. We will consider some examples of specific sets of bases in Sec. 
In Sec. [6l we compare this new protocol to the six-state protocol in an experimental 
setting and consider a general method of implementing the protocol for any choice of c and 
d. Finally, we summarise the results and compare the new protocol to existing quantum 
key distribution methods in Sec. [7] 

2 General form of the Protocol 

In quantum cryptography, there are two legitimate parties who wish to establish a shared 
sequence of letters from an alphabet such as a string of zeros and ones. Typically, these two 
parties have different roles: Alice prepares and sends quantum states, and Bob performs 

1 Except possibly a new theory of physics that allows operations beyond quantum mechanics (c.f. 
Popescu-Rohrlich boxes [7]). 
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measurements on the states he receives and records the outcomes. At the end of this 
quantum part of the protocol, the two parties then exchange information via a classical 
communication channel. A third party, Eve, attempts to gain information about some or 
all of the shared key without being detected. Eve can perform any operation allowed by 
quantum mechanics and can listen in on the classical part of the communication without 
being detected. We also assume that she has access to a high level of technology so that 
she can hide behind any system noise by replacing parts of the implementation by better 
components. The aim is to find protocols and implementations such that Eve is easily 
detected. 

We begin by presenting a new protocol that enables Alice and Bob to share a key and 
then discuss the effect Eve has on the states received by Bob. We will assume that Eve uses 
an intercept-and-resend attack and calculate error rates that allow the legitimate parties 
to detect her presence. There are other more sophisticated forms of attack available to Eve 
but we will not analyse them here; we simply remark that this form of attack provides a 
useful guide to the security of the protocol against more general attacks. 

We first present the highly-sensitive-to-eavesdropping (USE) protocol in its general 
form; encoding an alphabet, A, containing c = \A\ elements using d dimensional quantum 
systems. In Sec. 12.11 we give an explicit example of the protocol when used to encode a 
4-letter alphabet, say {0, 1, 2, 3}, using 3-dimensional quantum systems. A further example 
is provided in Sec. 16.11 where we discus the case of c = 3 and d = 2 in an experimental 
setting. 

The HSE-Protocol 

• Alice and Bob agree publicly on a method of encoding the c elements of A using states 
in C d by choosing bases B x = {\ipf ) G C d : i = 1 . . . d} for all x G A. They are free 
to choose any bases provided they are different in the sense that no two bases have 
any state in common. We will discuss the optimum choice in Sec. 01 Throughout 
the protocol, Alice and Bob will use bases chosen from the set {B x : x 6 A}. 

• Alice generates a random string, S, of letters from A that form the raw data she will 
attempt to share with Bob. 

• For each element, x € S, Alice generates c — 1 random numbers, a = (a\, . . . a c -i), 
between 1 and d. The numbers a serve as indices for states chosen from basis B x as 
she now prepares and sends the c — 1 states £ B x , k = I . . . c — 1, to Bob. 

• Bob chooses a sequence of c — 1 different letters of .A, xi, . . . ,Xk- When he receives 
the kth state, ), he measures it in the bases B Xh and records the measurement 
outcomes, b = . . . 6 c _i). 

• After Bob's measurements, Alice publicly announces the indices a keeping her choice 
of basis a secret. Using this information, Bob is (sometimes) able to deduce which 
basis Alice used and therefore to determine the element of S. 

• Bob tells Alice for which elements he was able to determine x. Unsuccessful attempts 
are discarded, leaving only the shared key. 

An element x 6 S is successfully shared between Alice and Bob when for every state 
\tpa k ) £ B x , k = I . . . c— 1, the index measured by Bob does not equal the index announced 
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by Alice, 7^ b/. for all k. If this happens Bob knows that none of his measurements were 
in basis B x and so his missing basis corresponds to the correct letter of the string, x. If 
Bob's measurement does equal the announced index for any k, he does not know if this 
was because he measured in the same basis as Alice or because of the non-zero overlap 
between vectors from different bases. This element of the string then fails. 

The protocol presented in [10] is then a special case of this protocol applied to a two- 
letter alphabet {0, 1} so that Alice needs only to send one state for each letter of S. Khan et 
al.'s protocol is interesting because it has a high error rate that approaches 50% for higher 
dimensional quantum systems if Alice and Bob use two mutually unbiased bases. Starting 
with the probability that the transmission of the element x is successful, we will analyse 
the performance of the general protocol in the following sections. We find that this general 
protocol has an error rate that approaches 100% when Alice and Bob use high-dimensional 
systems and a complete set of (d + 1) mutually unbiased bases. In Sec. [4] we will use a 
natural measure of distance between bases to argue that the optimal settings for Alice and 
Bob are indeed mutually unbiased bases. 
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2.1 A four-letter alphabet encoded using qutrits 

We now make the protocol explicit when applied to a four-letter alphabet, say A = 
{0,1,2,3}, encoded using three-dimensional quantum systems. Note that we can think 
of 0,1,2,3 as representing 00, 01, 10, 11 and therefore the key that Alice and Bob share 
as pairs of bits, for example, the string S = 213101 becomes 100111010001; this makes it 
easier to compare the bit efficiency of different protocols. We examine the case where Alice 
and Bob encode A using the bases 

1 

uj 2 

UJ 

1 1 \ 

(1) 



where the columns of the matrix B x correspond to the vectors \i/jf ), i = 1, 2, 3 of each basis. 

In order to send the first element of the string, say x = 2, Alice generates three random 
numbers a±, 02, 03 G {1, 2, 3} and sends the states \^ 2 1 ), \fpa 2 ) ana - I ^03)' Bob now measures 
in three different, randomly chosen bases resulting in the measurement outcomes b\, 62 and 
63. The element x is successfully transmitted if and only if a\ 7^ 61, 02 7^ &2 and 03 7^ 63 
since if this happens, Bob can be certain that he did not use the same basis as Alice. Bob 
must have performed measurements in the bases B°, B 1 and B 3 so that his missing basis 
corresponds to the correct element x = 2. The probability that an element is shared for 
each run of the protocol is given by 

^^('-ij =27' 

since there is a 1/4 chance that Bob does not use B 2 and a 2/3 chance that he does not 
measure index when using basis B x , x 7^ 2, for k = 1 ... 3. 

Each element of the string represents two bits and so, on average, in order to share one 
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bit of information Alice and Bob need to perform this procedure 27/4 ~ 7 times so that 
Alice has to send a total of 3 x 27/4 ~ 20.3 states. This is relatively high, for example in the 
BB84 protocol, Alice needs to send an average of only two states in order to successfully 
transmit one bit of information. However, as we will see in Sec the presence of an 
eavesdropper causes a much higher error rate. The present protocol therefore remains 
secure even if there is a very high level of system noise. 

2.2 Probability of success 

Having calculated the success rate for the protocol in the case of a four-letter alphabet 
encoded using a specific choice of bases of C 3 , we now consider the general probability of 
success. The protocol results in a letter, x, forming part of the shared key whenever the 
indices measured by Bob are all different from those announced by Alice, that is whenever 
ak ^ bk for k = 1, . . . , c — 1. For each state, indexed by k, Bob makes a measurement in 
basis B Xk so that the probability of measuring index a k is given by 

q k = prob(a fc = b k ) = |(C£lC fc }| 2 • 
Hence the success rate of the protocol is 

1 c_1 

n s = -T[{l-q k ), (2) 

c 

k=l 

the chance that none of the c — 1 bases chosen by Bob equal the one selected by Alice, B x , 
multiplied by the probability of never measuring the same index even though all of Bob's 
measurements are different to B x . In order to get a success rate per bit of information 
shared between Alice and Bob, called the bit transmission rate, 

TZ t = \og 2 {c)TZ s , (3) 

we multiply 1Z S by log 2 (c). 

This general formula depends on the choice of bases used to encode the alphabet, and in 
particular the modulus of the overlap between states from different bases. We will consider 
different bases used in the protocol in Sec. [Hand compare the bit transmission rate, IZt, 
with existing QKD protocols in the conclusion. 

3 Error rate introduced by an eavesdropper 

We have seen how the protocol allows Alice and Bob to create a shared key, we now consider 
the effect of an eavesdropper. In particular, we analyse the effect of an intercept-and-resend 
attack. That is, for each state sent by Alice, an eavesdropper performs a measurement on 
the system and then prepares and sends a new state to Bob. In effect, we can imagine the 
attack as being performed in two stages. Eve measures the state of the system and then 
discards it completely. Using the classical information corresponding to her measurement 
outcome, she then prepares a new system in a state that is as "close as possible" to the 
original. 

In general, Eve is free to use different measurements for each state sent by Alice. She can 
also send Bob a system in any state regardless of the measurement outcome. However, since 
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the states \ipa k ) have indices, a^, that are uniformly distributed, each subsequent measure- 
ment made by Eve is independent from the previous measurement outcomes. Therefore, 
there is no loss of generality in assuming that Eve always uses the same measurement basis, 
8 = {|ej) G C d , i = 1 . . . d}, corresponding to her optimal one. In addition, we assume that 
Eve sends the state corresponding to her measurement outcome since it is likely to be the 
state closest to \ipa k )- 

Alice and Bob can detect Eve's attack in one of two different ways; by detecting a 
change in the index of the state received by Bob, called the index transmission error rate 
(ITER); and by errors in the final shared key, called the quantum bit error rate (QBER). 
We begin by considering the ITER, which can be detected whenever Alice and Bob use 
the same bases, B x , and has been used in other QKD protocols to detect an eavesdropper 

unmans]. 



3.1 The index transmission error rate 

Suppose Alice sends the state ), Bob can detect Eve if he happens to perform a mea- 
surement in basis B x and his measurement outcome, j, does not equal i. This occurs with 
probability pi(x,x), where we define 

k=l j=l 

to be the probability that the index i changes when Alice prepares a state in basis B x and 
Bob measures the system he receives in basis B y . Since for any y and k, Eve measures one 
of the possible outcomes with certainty, 

d 

EK e *iv?>i 2 = 1 . ( 5 ) 

i=i 

Eqn. (j4]) can be written as 

d 

Pl (x,y) = l-Y J \mek)\ 2 \(e k m\ 2 , 

k=l 

one minus the probability that Bob measures a state with index i. 

The rate at which Alice and Bob can detect an index transmission error, IZjt, is 
calculated by averaging pi(x,x) over all indices, i, and letters of the alphabet, x S A. 
That is, 

^ c— 1 d 

x=0 i=l 

1 c— 1 d d 

= i-^EEEi^)! 4 - (6) 

X=0 8=1 k = l 

As with the probability of success, IZjt depends on the choice of bases. We will see how 
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this measure of the sensitivity of the protocol to eavesdropping can be understood as a 
measure of distance between the bases used by all three parties in Sec. [H Then in Sec. [5] 
we will consider some interesting examples of specific bases. 

3.2 The quantum bit error rate 

In addition to the index transmission error rate, Alice and Bob can detect an eavesdropper 
by calculating the error rate of the final shared key. Eve's intercept-and-resend attack may 
cause a change in the index in such a way that Bob adds an incorrect letter to his key. 
Just as in the original BB84 protocol, the legitimate parties can detect quantum bit errors 
by selecting a random subset of the key and openly comparing its elements. 

To see how an error in the key is created, suppose Alice attempts to share the letter 
x 6 A. If none of the indices measured by Bob equal the indices announced by Alice, 
Ofc 7^ bk for all k = 1 ... c — 1, Alice adds x to her key and Bob adds x. The letters, x and 
x, correctly coincide provided one of Bob's measurements was not in the basis B x since he 
adds the letter corresponding to his missing basis. If however, Bob did use B x , he adds the 
letter i/ito his key and there is an error in the shared key. Therefore, the proportion 
of key elements that contain an error, is given by the quantum bit error rate 

where; the factor is the probability that Bob uses the same basis as Alice in one of 
his c — 1 measurements; TZbe is the rate at which Bob adds incorrect letters to his key, 
called Bob's error rate; and TZk is the average probability that a bit is added to the key 
regardless of Bob's choice of basis, called the key rate. 

We now calculate the terms in Eqn. © starting with TZk- Given any vector of indices, 
a = (oi, . . . , a c _i), chosen by Alice and bases with indices y = (yi, . . . , y c -i) chosen by 
Bob, the probability that a k ^ b k for all k = 1 . . . c — 1 is given by 

c-1 

YlPa k (x,y k ). (8) 

fc=i 

where Pi(x, y) has been defined in Eqn. (j3J). Alice uses vectors from the set I = {(ai, . . . , o c -i) : 
ct£ G Z^} since she is free to repeat an index. Bob, however is more restricted, he must use 
each basis only once and therefore, choose a vector 

y £Y = {(yi, . . . , y c _ x ) : y k £ A and y k / yi for all k, I}. 
Hence, TZk is the average over all bases B x and elements of the sets I and Y, 

^ c— 1 c— 1 

Uk = dvw\ £ £ £ n ^ ^ 

1 111 x=o y eY &el k=i 

where \Y\ = c! and \I\ = dP^ 1 . 

The numerator in Eqn. ((JJ), TZbe, is the average probability that Bob adds an incorrect 
letter to his key. Such a bit error occurs when Bob uses the same basis as Alice and measures 
indices that are all different to those announced by Alice. To help calculate Bob's error 
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rate, we define the set Z to be 

Z = {(x, Z2, ■ ■ ■ , z c —i) '■ z k £ <A, Zk 7^ x and z^, 7^ z\ for all k, I}, 

that is, the first component of every z £ Z corresponds to the letter x used by Alice to 
encode the states. Therefore, Bob's error rate is given by 

- c— 1 c— 1 

Ube = dzW\ E E E II p«* (*> ( 10 ) 

' " ' x=0 zeZ ael k=l 

where we average over all outcomes that correspond to Bob adding an incorrect letter to 
his key and the set Z contains \Z\ = (c — 1)! elements. 

The rather complicated formula for IZqb given by Eqns. ((7|), ([9]) and (fTUl) has a simple 
form when Alice and Bob use only two bases in the protocol. The simplification is due to 
the fact that when c = 2, Bob's error rate TZbe = T^-it and hence 

w 2K K 

corresponding to the QBER obtained in [10] . We will also see that the general form of IZqb 
simplifies when applied to a specific choice of bases in Sec. [U Before doing so, we show 
how the error rate TZjt relates to a natural measure of distance between the bases of C d 
used by the three parties. 



4 Distance between bases 

In this section we consider the bases used in the QKD protocol as points in a higher- 
dimensional space. This setting allows us to understand the optimal strategy for the 
legitimate parties in terms of a natural measure of distance between two bases. We follow 
an approach similar to that presented in [16] : here, however, we will consider an alternative 
choice of origin so that the resulting space is an affine space rather than a vector space. 
We begin by associating to every normalised vector, \tp) S C d , the operator 

that lives in a d 2 — 1 dimensional space consisting of Hermitian operators of trace one. 
Equipped with the inner product 

if) ■ <f> =Trip(J), 

this is an affine space in which a basis B = ■ ■ ■ , \ipd)} of C d is identified with a 

set of operators {ipi,^, • ■ • , V'rf} spanning a d — 1 dimensional plane. To define a distance 
between two such planes, we perform a similar procedure and embed them in an even larger 
space so that to each basis B we associate the matrix 

^1 



Vd 



[■01-02 ■■■ipd] 
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that projects onto the plane spanned by the basis vectors {ipi,ip2, ■ ■ -tpd}- Acting on an 
arbitrary pure state, (ft, the operator ^ describes the action of performing a measurement 
in basis B since the non-zero elements of ^(p are \{tpi\<P)\ 2 'fpi ^or i = 1 . . . d. 

The matrices ^ are elements of a (d 2 — l) 2 dimensional space (called an affine Grass- 
mannian), in which a natural measure of distance between two points, $ and is the 
chordal Grassmannian distance 

D 2 (<&, \P) = 1 — Tr$*. (11) 
Applying this distance measure to two points, $ and associated with bases reads 





[^1^2 ■■■Ipd] 




Ypw2 ■ 


■ <Pd] 


r t i 

<Pi 

T 
T 

. fd . 





-. d d 
a i=l j=l 



a i=i j=i 

Hence the civercige distcincB, D avera g e ^ between Eve's basis E and the bases chosen by Alice 
and Bob, B x , x = . . . c — 1, is given by 

1 c_1 

Daverage = ~ ^ ] D (B , 

= i-^EEEiwir ( 12 ) 

x=0 i=l fe=l 

the index transmission error rate caused by Eve's intercept-and-resend attack. 

This distance measure provides an intuitive feel as to how the three parties in the 
protocol should behave: Alice and Bob aim to maximize the error rate TZjt by separating 
their bases as much as possible; whilst Eve chooses a basis that minimises the average 
distance between all of the bases chosen by Alice and Bob. We will begin the next section 
by making these statements more precise and find that they lead to the conclusion that 
Alice and Bob should use a complete set of mutually unbiased bases. 

5 Optimal choice of bases 

In this section we consider specific choices of bases used by Alice and Bob in the HSE- 
protocol. The protocol is entirely general and any set of bases can be used to encode the 
alphabet. There are likely to be many considerations in choosing a suitable set such as 
the ease of preparing and measuring states in each of the prescribed bases. In this section 
we will not worry about experimental difficulties but simply consider the optimal choice 
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from a theoretical perspective. Motivated by the distance measure in Sec. 0]we begin by 
considering a set of mutually unbiased (MU) bases. 

5.1 Mutually unbiased bases 

Two bases B x = {\ipf ), i = 1 . . . d} and B y = {\ipf ), i = 1 . . . d} are called mutually unbiased 
if the modulus of the inner product of vectors from different bases is uniform, 

M\i>))\ = K, (13) 

which in finite dimensions means that k = 1/ \[d. Schwinger noted [17] that two such bases 
represent measurements that are "maximally non-commuting" in that measuring in one 
bases reveals no information about the outcome of a measurement in the other basis. For 
example, in dimension d = 2, if we set a Stern-Gerlach experiment to measure spin in the 
x direction, we gain no information about spin in the z direction. 

This maximal lack of information about measurement outcomes from other bases is 
captured by the distance measure introduced in Eqn. (fTTI) . The distance between any two 
bases $ and is bounded by 

< D 2 ($,y) < 1- -, 

where the lower bound is obtained when and span the same subspace and the upper 
bound is realised when they are mutually unbiased. Since Alice and Bob wish to maximize 
the average distance between all of the bases they use, a natural strategy is to use as many 
MU bases as possible. They cannot use more than d + 1, called a complete set, since it is 
impossible to fit any more d — 1 dimensional planes with the correct overlap into a space 
of dimension d 2 + 1 [16] . In dimension d = 3, the four bases given in Eqn (pQ) constitute 
a complete set of MU bases. In all other prime-power dimensions, a complete set of MU 
bases has been constructed |18| . However, for composite dimensions d = 6,10,12,... the 
maximum number of bases satisfying the conditions f)13[) . remains an open problem. 

We now turn our attention to the optimal strategy of an eavesdropper. As before, 
we assume that she uses an intercept-and-resend attack and following the arguments of 
Sec. El only uses one basis corresponding to her optimal choice. Eve's optimal strategy is 
essentially a minimisation problem subject to some constraints. The functions she wishes 
to minimise are the error rates TZqb and TZit, and the constraints come from the fact that 
Eve must use a set of d orthonormal vectors. By approaching this problem numerically, 
Khan et. al. provide evidence that for c = 2, the index transmission error rate has a global 
minimum when Eve's basis spans the same subspace as one of the bases chosen by Alice 
and Bob [10] . In other words, Eve's optimal strategy is to simply pick one of the bases 
used by the legitimate parties. 

Eve has many alternative eavesdropping strategies at her disposal. For example, for 
the case when d = c = 2, Eve could use the so-called Breidbart basis that is halfway 
between the two bases used by the legitimate parties [19]. In the BB84 protocol, such a 
strategy has been shown to increase the chance that Eve reads the bit correctly although 
it does not reduce her chance of being detected [20] . However, when the legitimate parties 
use a complete set of MU bases, there is no basis that is "halfway" between all of them. 
There are many issues concerned with finding the optimal strategy of an eavesdropper 
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[211 [22l [23| [24"| . In the following, we will assume that Eve picks one of the bases used by 
the legitimate parties and consider the protocol when Alice and Bob use a set of c MU 
bases. 

There is no loss of generality in assuming that Eve's basis is given by £ = {|ej) S 
C d , i = 1 . . . d} = B°. Under this assumption, the distance between the bases used by all 
three parties is 

zero if B x corresponds to £ or maximal otherwise. Hence, the index transmission error rate 
for a set of c MU bases is given by 



<r>MUB 

l-Cjrp 



i£i / 1 

X — 1 

(c- 1 ^- 1 ) , (14 ) 
cd 



We see that the error rate is an increasing function of both c and d and that Eqn. flTJ 
is indeed maximized if Alice and Bob use a complete set of MU bases. In which case, the 
index transmission error rate of the protocol equals 



d- 1 

" " " d + i 



and therefore tends to 100% as d tends to infinity. 

The index transmission error rate introduced by an intercept-and-resend attack in Eqn. 
(I14j) is equal to the quantum bit error rate of the BKBOl-protocol of Bourennane et al. |12j . 
It is a natural generalisation of the BB84 protocol and has been further analysed in |25U13j . 
The BKBOl-protocol, the d letters of an alphabet are encoded into the indices of one of c 
mutually unbiased bases. Alice sends a state \ip%), where x = 1 . . . d and a = . . . c — 1, 
and after Bob's measurement, announces the basis, a, which she used to prepare the states. 
Hence, whenever Bob performs a measurement in the same basis B b , they share the letter 
x £ A. Note that in contrast to the HSE-protocol, the roles of c and d are reversed. In the 
conclusion, the error rates and the number of states needed to successfully share one bit 
of the key for the BKB01 protocol are compared to the HSE-protocol. 

The quantum bit error rate, TZqb, given in Eqn. (J7]), also simplifies significantly when 
Alice and Bob use a set of c MU bases and we assume that Eve's basis equals £ = B°, say. 
Under these assumptions, the probability that an index changes is zero if all three parties 
use the same bases and one minus the probability of measuring the correct index if any 
one of the parties uses a different basis 

v(x v)-l ° if (*,V) = (0,0) 

M ,V) ~ I 1-J if(x,y)/(0,0). 

Therefore, the product of probabilities given in Eqn. (|8|), 

c-l 



k=l 
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depends solely on whether any of the terms correspond to (x, y^) = (0,0). 

To calculate the number of non-zero terms in TZbe, given in Eqn. (jlOl) . note that one 
of Bob's bases is always equal to B x and therefore (x, yu) = (0, 0) for some k, if and only if 
x = 0. Hence, the proportion of non-zero terms in Eqn. fjlOf) is equal to (1 — 1/c). Similarly, 
when the vectors y GY, the number of non-zero terms in Eqn. ([9]) is (l — \ + |Y||/|c, 
so that Bob's error rate and the key rate are given by 



n BE = 1 1 - - 



c 



K h ( I -- + 4) 



1- 
















c-1 



c-1 



respectively. Therefore, for a set of c mutually unbiased bases, the error rate TZqb is given 

by 



which, surprisingly, does no£ depend on the dimension of the quantum systems used in 
the protocol. However, it is of course limited by the number of MU bases that can be 
constructed in a given dimension c < d + 1 and may also be limited by the conjectured 
non-existence of complete sets of MU bases in composite dimensions. 

Whilst constructions of complete sets of MU bases are known for prime power dimen- 
sions, and are well understood in low dimensions [26] their existence is an open problem 
for composite dimensions. In fact, there is considerable numerical |27[ [28] and analytical 
|29[ [30] evidence to suggest that there are no more than three MU bases in dimension six. 
Hence restricting the measurements to MU bases could mean that the protocol is more 
efficient in prime power dimensions than in composite dimensions, for example, using six 
MU bases in dimension five the error rate IZit is 2/3 ~ 66.7% were as if only three MU 
bases are available in dimension six the maximum error rate is 5/9 ~ 55.6%. The situation 
for the QBER is even more pronounced since 7Zqb B depends only on the number of MU 
bases available and not on the dimension. As such it would be better to use quantum 
systems of dimension three since it is possible to construct four MU bases than to use 
systems of dimension d = 6, for which we only know how to construct three bases with the 
required overlap. 



5.2 Approximate mutually unbiased bases 

It is not clear that a complete set of d + 1 mutually unbiased bases exists in all dimensions. 
Therefore, in order to consider the limiting behaviour of the protocol, we consider an 
alternative choice of bases for which constructions are known in all dimensions. As with a 
complete set of MU bases, they have the property that the error rate TZit tends to 100% 
as the dimension of the quantum systems used by Alice and Bob increases. 

By relaxing the uniform modulus condition (|13j) . Klappenecker et al. [31] define ap- 
proximate mutually unbiased bases (abbreviated as AMU bases) which have the property 
that the modulus of the inner product between vectors from different bases is small. In 
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particular they define a set of d 2 bases such that 



2 + Old^ 1 / 10 ) 
|<^y>|<l±i4| L forx/y, 

and for all where f(d) = 0(d^ 1 ^ 10 ) means that there exists a constant K > such 
that | /(d) | < Kd~ l / W for all d > 1. Hence if Alice and Bob use all d 2 bases, and Eve uses 
one of the bases in her intercept-and-resend attack, the index transmission error rate is 
bounded from below by 



<r>AMUB ^ i 

K IT > 1 d3 



1 



d + (d 2 - 1)(2 + tfcT 1 / 10 ) 4 ! . (16) 



The unknown constant in Eqn. (|16|) prevents us from saying anything in specific dimen- 
sions, but we can still consider the protocol when Alice and Bob use a set of AMU bases in 
the limit as d tends to infinity. We see that such a set of approximate MU bases defined so 
that they minimise the value of k in Eqn. Q13|) and therefore maximise the distance mea- 
sure defined by Eqn. (fl~2j) are good at detecting the eavesdropping by Eve. Even though 
a complete set of MU bases may not exist in every dimension, we can at least define a set 
of AMU bases that do exist in all dimensions and for which the ITER tends to 100%. 



6 Implementations 

In this section, we present a specific example of how Alice and Bob can use the HSE- 
protocol to form a shared key. We also calculate the quantum bit and index transmission 
error rates that allow Alice and Bob to detect an eavesdropper for this choice of c and d. 
Finally, we discuss a practical implementation of the protocol that could be used for any 
values of c and d using photon states and multiport beam splitters. 

6.1 An alternative "six-state" protocol using qubits 

In the six-state protocol [241 132j . Alice prepares and sends one of six states corresponding 
to the points on the Bloch ball (±1,0,0), (0, ±1,0) and (0,0, ±1). These six states form 
three MU bases B°, B 1 , and B 2 corresponding to 

{|0>, |1)}, {-L(|0) + -L(|0) - |1»}, and {-L(|0) + -±=(|0> - i|l»} 

respectively. After receiving a state from Alice, Bob performs a measurement in one of 
the three bases and records his outcome. Alice announces which of the bases she used to 
prepare the state and if Bob used the same basis they are able to share an element of the 
key. When the bases used by Alice and Bob coincide, Bob can correctly determine the 
letter because his measurement outcome must correspond to the state prepared by Alice 
(in the absence of an eavesdropper). 

Using the polarization of photons to encode the states, Enzer et. al. have implemented 
the six-state protocol experimentally [33 j . The three bases in their scheme correspond to 
horizontal/vertical (H/V), diagonal ±45°/— 45° (D/d) and left/right circular (L/R) polar- 
ization; the three states H,D and L encoding a zero and V,d,R a one. By simulating an 
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intercept-and-resend attack Enzer et. al. find a bit error rate of 34.0 ± 1.4% in agreement 
with the theoretical value of 33.3%. 

In order to implement the HSE-protocol, the six-state scheme presented in |33j requires 
only a slight modification. The preparation and measurement of the states remains the 
same; the difference being the method of encoding the alphabet. Here, we will use the 
polarizations H/V to encode a zero, D/d a one and L/R a two. That is, our scheme uses 
a three letter alphabet A = {0, 1, 2} encoded into the choice of basis; B°, B 1 , or B 2 . The 
indices of the states are either zero or one corresponding to H,D, and L or V,d and R 
respectively. 

As before, Alice chooses one of the bases £>°, B 1 , or B 2 but this time sends two states. 
That is, suppose Alice chooses to encode the bits in the H/V basis, then she sends either 
HH, HV, VH or VV. Bob now makes a measurement in two different bases and records 
the indices corresponding to his outcomes. Alice announces the indices, either 00, 01, 10 
or 11, equal to her choice of prepared states. She does not announce the basis. Using the 
indices announced by Alice and his measurement outcomes, Bob hopes to determine the 
basis used by Alice. 

An element of the key is shared whenever Bob's indices both differ from the indices 
announced by Alice. For example, if Alice sends states with indices 01, an element of the 
key is shared if and only if Bob's measurement outcomes are 10. For this scheme, the 
average rate at which a bits are shared between Alice and Bob is given by 

TZt = log 2 (3)~fl - « 13.2%, 

since the probability that Bob does not use the same basis as Alice in both of his measure- 
ments is 1/3 and there is a 1/2 chance that he does not measure the announced index when 
using a different basis. The pre-factor of log 2 (3) is due to the fact that when an element 
of the key is shared it corresponds to an element of of a three letter alphabet. 

Whilst the bit rate is 13.2%, compared to 33% for the six-state protocol, the number of 
sates Alice must send in order to share one bit of information is much higher than in the 
six-state protocol. For each attempt at sharing a letter of the alphabet, Alice must send 
two states. Therefore the average number of states, M s = 2 x 100/13.2 ~ 15.2 which is 
five times more than the 3 states needed to share one bit when implementing the six-state 
protocol. 

We find that although this protocol is more expensive than the six-state protocol, it is 
also more sensitive to an eavesdropper. The quantum bit error rate of an intercept-and- 
resend attack of this new protocol is given by 

^» = (i - 1 + p)" 1 

following Eqn. (|15|) : representing a significant improvement over the 33.3% error rate of the 
six-state protocol. We have used the same six states as the six-state protocol but this new 
method of encoding the letters of an alphabet is more sensitive to an intercept-and-resend 
attack. 
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6.2 Possible implementation using multiport beam splitters 

A recent experiment has implemented quantum state tomography using a complete set 
of MU bases in dimension d = 4 [34] . It demonstrates that tomography with MU bases 
is not only optimal in theory, but is more efficient than standard measurement strategies 
in practice. The scheme presented in |34| therefore provides a way of measuring two- 
qubit photon states in one of five mutually unbiased bases in dimension four. However, 
to implement the QKD presented in Sec. [2] a set of c MU bases, we also need to reliably 
prepare the relevant states. Such a scheme for c = 2 MU bases has been provided by Khan 
et al. [10] and can be extended to any number of mutually unbiased bases. This follows 
from the fact that any discrete unitary operator can be realised using a series of beam 
splitters and mirrors [35]. These so called multiport beam splitters are symmetric when 
they correspond to MU bases [36]. 

The protocol could be implemented as follows. Alice uses a single photon source such as 
a spontaneous parametric down conversion crystal. She now chooses one of c — 1 multiport 
beam splitters, or to bypass the beam splitters altogether. This gives one of the c bases 
labeled by the letters of A required for the protocol. Each vector \ifjf) of her chosen basis, 
B x , is encoded into the output paths of the corresponding beam splitter by sending a single 
photon into the input port i. Bob uses the same beam splitters in order to measure the 
state of each photon he receives. He does this by first sending it through one of the beam 
splitters (or bypasses them to measure B°) and then detecting it in one of the al output 
ports. When c = 2, a natural choice for the two MU bases is to use the standard basis 
£>° = {\i),i = . . . d — 1} and the so called Fourier matrix which has entries F{j = uj % i /Vd, 
for i,j = 0. . . d— 1 where u) = exp(2iri/d) is the dth root of unity (which for d = 3 is given 
by B 1 in Eqn. ([1])). This scheme corresponds to the one presented in [10] and could be 
realised using Bell multiport beam splitters [37j . 

7 Conclusion 

We have presented a novel protocol that enables two parties to generate a shared key. It 
is special in that the presence of an eavesdropper who uses an intercept-and-resend attack 
creates a high error rate. This has the practical advantage of allowing Alice and Bob to 
detect Eve even if the system noise in their implementation is high. We have analysed 
two error rates that allow for the detection of an eavesdropper; the index transmission 
error rate (ITER) and the quantum bit error rate (QBER). Both of these measures of 
the sensitivity to eavesdropping tend to one as the parties use more bases to encode the 
elements of the key and, in the case of the ITER, if they use higher dimensional systems. 

Table [JJ compares the essential features of the HSE-protocol to existing QKD protocols: 
the original quantum key distribution protocol of Bennett and Brassard [5] is referred to 
as BB84; the generalisation of BB84 to a protocol that uses c mutually unbiased bases and 
d-dimensional quantum systems |12| is called BKB01; the case where three MU bases are 
used in dimension two corresponds to the six-state protocol (6-state) (24J [32] ; the protocol 
presented in Sec. [2]is denoted HSE (which stands for highly sensitive to eavesdropping); the 
case where only two bases are used corresponding to the protocol of Khan et al. (KMB09) 
[TO] . Throughout the table, we assume that the HSE-protocol is applied to a set of c 
mutually unbiased bases. The pair of numbers, (d, c), in the second column correspond to 
the dimension of the quantum systems used in the protocol and the number of elements in 
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Table 1: Table comparing different QKD protocols in dimensions d = 2,3 and 7; TZqb and 
IZjt are the quantum bit and index transmission error rates of an intercept-and-resend 
attack, respectively; IZt is the bit transmission rate defined in Eqn ([3j); finally, N s is the 
average number of states Alice must send in order to share one bit with Bob. Note that 
the KMB09-protocol is a special case of the HSE-protocol. 

the classical alphabet. 

The third and forth columns of Table Q] show the QBER and the ITER respectively. 
The error rates, which have been calculated using Eqns. (|14p and (|15p . show that by using 
d + 1 MU bases, Alice and Bob can increase the QBER beyond that of BKB01. The fifth 
column displays the rate at which the two legitimate parties sharing one bit of information; 
that is TZ S has been normalised so that it gives a per bit success The last column 

then shows the average number of states Alice needs to send in order to successfully share 
one bit of her key with Bob. This final column clearly demonstrates the trade-off between 
the error rate and the "cost" of producing a shared key. It is possible to make it easier to 
detect Eve but this comes at the expense of reducing the bit transmission rate. 

At first sight, the protocol appears to have no special features relating to the dimension 
of the quantum systems used by Alice and Bob. However, an analysis of the optimal bases 
reveals that it is more efficient when the legitimate parties use systems of prime-power 
dimensions. In prime-power dimensions Alice and Bob can use constructions of d + 1 
mutually unbiased bases that are conjectured not to exist in composite dimensions such 
as d = 6, 10, 12, etc. In addition, in some dimensions, inequivalent sets of c MU bases 
are available. For example in dimension d = 4, there exits a three-parameter family of 
triples of MU bases |26|, [38] or in dimension d = 16 there is a 17-parameter family of 
pairs of MU bases [39]. It may be that within these families there are some bases that 

2 Note that when the BKB01 protocol is applied to two MU bases in dimension d = 7, the rate at 
which bits are shared between Alice and Bob is larger than 100%. In this case, the legitimate parties use 
7-dimensional quantum systems so that each time they are successful, they share an element of a 7 letter 
alphabet. Hence, the number of states Alice needs to send in order to share one bit is 0.7, i.e. less than 
one. 



16 



are experimentally more accessible than others. For example, Romero et al. [3Q] have 
considered a notion of inequivalent sets of MU bases involving the entanglement content 
of the bases and therefore, one aspect of the experimental difficulty in measuring and 
preparing systems in the corresponding bases. 

If an experimenter finds that a particular measurement is easy to implement and that 
quantum systems prepared in the corresponding basis are readily available, they can use 
the HSE-protocol to distribute shared keys. Given the analytical form of the bases, we 
have shown how to calculate the error rate and the rate at which elements of a key are 
generated. Hence, to some extent, the protocol can be made to fit around experimental 
conditions, the question is then if the system noise enables an eavesdropper to disguise 
their presence. It may be that in practice it is better to search for measurements that can 
be performed efficiently in the laboratory (or in a purpose built device) than to find the 
analytical optimal bases. 

In recent years, quantum physicists have realised that finite dimensional complex linear 
spaces are surprisingly rich both in physical content and from a mathematical perspective. 
This setting has led to many important physical discoveries and in particular, the ability 
to distribute keys in a secure way. In this paper, we have explored this mathematical 
structure further and found that, at least in principle, Alice and Bob can make it very 
hard for Eve to hide. 
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